On 10/8/07, James Bennett <[EMAIL PROTECTED]> wrote:
> In the default setup, the URL /accounts/password/reset/ will, provided
> the user inputs their email address correctly, send out a a new
> password.

Which is an excellent way to partially lock someone out of the site,
by preemptively changing their pasword (and emailing them the new
one).  This operation should really email a challenge URL which, if
visited, leads to a "set new password" page.

  Bill

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Django users" group.
To post to this group, send email to django-users@googlegroups.com
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/django-users?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to